United States-English |
|
|
HP-UX System Administrator's Guide: Security Management: HP-UX 11i Version 3 > Chapter 9 HP-UX Role-Based Access ControlTroubleshooting HP-UX RBAC |
|
The following is a list of the primary mechanisms used to troubleshoot and debug HP-UX RBAC:
The most common bugs are caused by manual editing of the HP-UX RBAC databases, resulting in syntactically invalid configurations or in configurations that are inconsistent between databases (for example, a role in /etc/rbac/user_role that is not defined in /etc/rbac/roles). To assist in diagnosing these common mistakes, HP-UX RBAC includes an rbacdbchk command. This command reads through the HP-UX RBAC databases and prints warnings where incorrect or inconsistent configuration entries are found:
On a correctly configured system, the rbacdbchk command produces no output, indicating no errors are present. The second method for detecting problems is to run the privrun command with the -v option (verbose mode). In verbose mode, privrun provides additional information about the entries that the input command matched and the status of the authorization checking, as well as other relevant data. In many cases, this output clarifies the issue causing privrun to fail. Specify the -v option multiple times for additional levels of verbose output. The following is an example of the privrun -v output with the ipfstat command:
|
Printable version | ||
|